Networking Forums

Networking Forums > Computer Networking > Windows Networking > A security issue about windows workgroup logon

Reply
Thread Tools Display Modes

A security issue about windows workgroup logon

 
 
Frank
Guest
Posts: n/a

 
      07-14-2004, 03:28 PM
Hi All,



After testing I found that when a win2k local user account is having the same logon name and password as a win2k domain user account (No matter whether or not the win2k machine joins the domain), it then has the same access right to the domain resources which are assigned permission to the domain user account.



eg: Machine 1: win2k pro, workgroup, local user name: user1, pw: 123456

Machine 2: win2k domain controller with domain user account: user1, pw: 123456

when loggon locally to the win2k pro machine using credential user1, 123456, I can freely access any resource that the domain account user1 has permssion.



This is indeed a security issue although the chance of such co-incidence is small. By right, if user logon as local user, he/she should provide domain user credentials when accessing domain resources.



This will not happen for 2 identical domain users accounts which exist in two different domains. And I believe even for the win2k3 domain it is the same.



Does anyone knows where to find the explanation for such an issue, is it by design or a security hole?



Thanks

Frank

 
Reply With Quote
 
 
 
 
Bill Grant
Guest
Posts: n/a

 
      07-15-2004, 07:27 AM
I think you will find that this has always been the case. When a
machine which is not a domain member tries to access a domain resource, the
domain controller queries the machine for its credentials. If the
workgroup/username/password exactly matches a valid
domain/username/password, the logon credentials are accepted by the domain
controller. The domain controller trusts the local machine logon
credentials.

"Frank" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
Hi All,



After testing I found that when a win2k local user account is having the
same logon name and password as a win2k domain user account (No matter
whether or not the win2k machine joins the domain), it then has the same
access right to the domain resources which are assigned permission to the
domain user account.



eg: Machine 1: win2k pro, workgroup, local user name: user1, pw: 123456

Machine 2: win2k domain controller with domain user account: user1, pw:
123456

when loggon locally to the win2k pro machine using credential user1,
123456, I can freely access any resource that the domain account user1 has
permssion.



This is indeed a security issue although the chance of such co-incidence is
small. By right, if user logon as local user, he/she should provide domain
user credentials when accessing domain resources.



This will not happen for 2 identical domain users accounts which exist in
two different domains. And I believe even for the win2k3 domain it is the
same.



Does anyone knows where to find the explanation for such an issue, is it by
design or a security hole?



Thanks

Frank


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows 2008 workgroup security Arne Garvander Windows Networking 10 03-17-2009 07:37 PM
Windows CE 5.0 PDA - Wireless Network Security issue Clara Wireless Networks 1 11-05-2007 07:17 PM
No logon server available - Windows 2003 Trust Issue? NS Issue? newsgroups.jd@gmail.com Windows Networking 15 08-21-2006 07:38 PM
frustrating logon issue on windows 2003 server clients rua17 Windows Networking 4 11-04-2004 12:20 AM
Cached User credentials (no logon box) // Security issue??? Gilbert Windows Networking 1 09-23-2004 07:28 PM



1 2 3 4 5 6 7 8 9 10 11